CVE-2020-35125 is a critical cross-site scripting (XSS) vulnerability affecting Mautic versions prior to 3.2.4, specifically within its forms component. This flaw allows remote attackers to inject malicious JavaScript through the mautic[return] parameter, leveraging a different attack method related to the Referer concept than a related CVE. With a CVSS score of 9.6 (Critical), it presents a high risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations using affected Mautic versions should prioritize patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.16.5CPE matchmatch criteria | cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.2.4CPE matchmatch criteria | cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.